Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote attackers to gain full administrative control over the camera.
CVE-2026-79396
NONE
EPSS 0.18%
Updated Sep 11, 2026
CVE Details
CVE ID
CVE-2026-79396
Published Date
Sep 11, 2026
Vendor
Not specified
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.18%
Likelihood of exploitation in next 30 days
Percentile:
7.8th percentile (higher than 7.8% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory